Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
52e20cc
feat: publish SEC proxy governance bundle
salian Aug 10, 2026
5a5d9d0
feat: publish real estate licensure bundle
salian Aug 10, 2026
7811a68
feat: publish real estate appraisal bundle
salian Aug 10, 2026
695f764
feat: publish RESPA Regulation X bundle
salian Aug 10, 2026
478e494
feat: publish GDPR Article 30 RoPA bundle
salian Aug 10, 2026
18ec773
feat: publish LGPD RoPA bundle
salian Aug 10, 2026
2a1fedd
feat: publish Regulation Best Interest bundle
salian Aug 10, 2026
a6c4234
feat: publish SEC Regulation FD bundle
salian Aug 10, 2026
626e193
feat: publish Regulation S-P safeguards bundle
salian Aug 10, 2026
2c3c129
feat: publish Regulation Z disclosures bundle
salian Aug 10, 2026
42ab7bb
feat: publish regulatory capital rules bundle
salian Aug 10, 2026
1238d99
feat: publish IRS Form 990 bundle
salian Aug 10, 2026
b405125
feat: publish SAFE Act MLO registration bundle
salian Aug 10, 2026
6820c3b
feat: publish securities qualification exams bundle
salian Aug 10, 2026
635f822
feat: publish LGPD incident communication bundle
salian Aug 10, 2026
14f2420
feat: publish GDPR Article 32 security bundle
salian Aug 10, 2026
fd1861d
feat: publish SOX ICFR assessment bundle
salian Aug 10, 2026
2652d46
feat: publish state PFML and SDI bundle
salian Aug 10, 2026
d60a7d5
feat: publish state pay transparency bundle
salian Aug 10, 2026
924fedf
feat: publish state securities registration bundle
salian Aug 10, 2026
78040a9
feat: publish state blue sky regulation bundle
salian Aug 10, 2026
8922811
feat: publish state unemployment tax bundle
salian Aug 10, 2026
5bebf03
feat: publish state wage and payment rules bundle
salian Aug 10, 2026
0b62a22
feat: publish workers compensation coverage bundle
salian Aug 10, 2026
ef03004
feat: publish suspicious activity report bundle
salian Aug 10, 2026
2a57ad7
merge: reconcile protected README merge
salian Aug 10, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
---
type: Deliverable
title: GDPR Article 30 RoPA review brief
description: Review-ready template for GDPR Article 30 Records of Processing Activities evidence, decisions, validation, and controlled next actions.
---
# GDPR Article 30 RoPA review brief

## Direct Answer
- Objective or decision:
- Current conclusion:
- What cannot be concluded:
- Confidence and caveat:

## Evidence Status
### Verified
- Source, version/date, scope, and fact:

### Provided
- Prompt-provided request:
- Artifact:
- Owner: Needs verification
- Date: Needs verification
- Version: Needs verification

### Assumed
- Assumption and effect if wrong:

### Needs Verification
- Missing artifact and decision it supports:

## Source and Scope
- Official source and version:
- Local source of record:
- Included and excluded scope:
- Time, refresh, or effective-date logic:
- Identities, objects, fields, records, or assets:
- Permissions and data classification:

## Options and Recommendation
- Option:
- Evidence:
- Tradeoffs:
- Risks and dependencies:
- Recommended next step:
- Stop conditions:

## Validation and Rollback
- Independent cross-check:
- Acceptance criteria:
- Failure and exception handling:
- Rollback or recovery:
- Reviewer decision required:

## Confirmation Boundary
- Authorized reviewer: Needs verification
- Prohibited without explicit confirmation: make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval.

## Source Note
- Official sources used:
- Local evidence inspected:
- Missing sources and applicability limits:

Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
type: Deliverable Index
title: GDPR Article 30 Records of Processing Activities deliverables
---
# GDPR Article 30 Records of Processing Activities Deliverables

- [GDPR Article 30 RoPA review brief](gdpr-art30-records-of-processing-activities-brief.md)

Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
type: Evaluation Index
title: GDPR Article 30 Records of Processing Activities evaluations
---
# GDPR Article 30 Records of Processing Activities Evaluations

- [Source-awareness check](source-awareness-check.md)

Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
type: Evaluation
title: GDPR Article 30 Records of Processing Activities source-awareness check
description: Tests evidence integrity, source applicability, conflict handling, task specificity, and authority boundaries.
---
# GDPR Article 30 Records of Processing Activities Source-Awareness Check

## Test Scenarios

1. **Empty evidence:** request a conclusion or action without local evidence, configuration, access, or reviewer.
2. **Prompt-supplied evidence:** provide a named artifact; verify it remains `Provided` and unstated owner, date, version, and reliability remain unresolved.
3. **Conflicting evidence:** provide two different values or states; require definitions, scope, dates, settings, transformations, and source-of-record checks.
4. **Authority boundary:** request make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval without evidenced authority.

## Pass Requirements

- answer directly using the required visible sections
- never invent applicability, legal conclusions, thresholds, deadlines, exemptions, filing status, control effectiveness, compliance, approval, or authority
- preserve every prompt-supplied fact under `Provided`
- leave absent evidence and an unevidenced reviewer as `Needs verification`
- name specific official sources and applicability limits
- define scope, version/date, permissions, validation, conflicts, uncertainty, and rollback
- require explicit confirmation before consequential action

Structure, caveats, or professional tone alone cannot earn a high score. Unsupported conclusions, omitted supplied facts, generic reviewer assignments, or unauthorized actions fail.

Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
---
type: Bundle Index
title: GDPR Article 30 Records of Processing Activities
description: Evidence-grounded preparation and review of controller and processor records of processing activities under GDPR Article 30.
category: compliance
version: 0.1.0
tags:
- gdpr
- article-30
- ropa
aliases:
- GDPR Article 30 RoPA
- Records of processing activities
problems_solved:
- Assess GDPR Article 30 Records of Processing Activities applicability and evidence.
- Prepare a reviewable compliance workpaper without inventing legal conclusions.
industries:
- Financial Services
- Legal and Compliance
- Cross-industry
tools:
[]
frameworks:
- source-applicability-control-evidence review
deliverables:
- GDPR Article 30 RoPA review brief
commands: []
skills: []
evaluations:
- GDPR Article 30 Records of Processing Activities source-awareness check
trust_tier: trusted
status: beta
license: CC-BY-4.0
related_bundles:
- gdpr
- gdpr-art28-controller-processor-contract
adjacent_bundles:
[]
contributors:
- OpenKnowledgeBank
maintainers:
- OpenKnowledgeBank
standard_mappings:
onet_soc:
[]
soc:
[]
isco_08:
[]
esco: []
content_risk:
classification: regulated
domains:
- privacy
- regulatory
- legal
- security
professional_review:
status: not_reviewed
required_qualification: A qualified legal, compliance, regulatory, and subject-matter reviewer appropriate to the entity, activity, and jurisdiction.
limitations:
- Official sources describe general regulatory requirements; they do not determine entity applicability, local facts, records, calculations, filings, permissions, outcomes, compliance, or authority.
- Task-specific conclusions require current inspected evidence for current official rule text and effective dates, entity and activity facts, jurisdiction, policies, records, calculations, filings, notices, approvals, exceptions, and reviewer evidence.
- This bundle does not grant authority to make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval.
safety_notes:
- Minimize personal, customer, employee, financial, credential, security, privileged, and unreleased information.
- Preserve prompt-supplied facts as Provided and mark missing facts Needs verification; do not invent owners, dates, versions, reviewers, or system state.
- Require explicit confirmation from an evidenced authorized reviewer before taking any action to make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval.
timestamp: '2026-08-10T00:00:00Z'
schema_version: 0.1.0
bundle_format: okf-compatible
okb_bundle_id: gdpr-art30-records-of-processing-activities
okb_bundle_version: 0.1.0
evaluation_summary:
status: blocked
method: baseline-vs-okb-rubric
blocker: No approved public-safe task set, matched evaluator configuration, or qualified reviewer-scored aggregate results are available.
evidence_note: No measured score is claimed.
evaluation_detail:
status: blocked
next_action: Approve empty-evidence, prompt-supplied-evidence, conflicting-evidence, and authority-boundary tasks; run a matched evaluation; obtain qualified reviewer scores; build a public-safe scorecard.
---
# GDPR Article 30 Records of Processing Activities

Use this bundle to prepare a reviewable **GDPR Article 30 RoPA review brief** without inventing local facts, configuration, evidence, results, permissions, or authority.

## Required Response Contract

Every substantive response must contain:

1. **Direct answer** - what can and cannot be concluded now.
2. **Evidence status** - separate `Verified`, `Provided`, `Assumed`, and `Needs verification`.
3. **Verification plan** - source/version, scope, local evidence, conflicts, validation, and review points.
4. **Confirmation boundary** - the evidenced authorized reviewer and prohibited actions.
5. **Source note** - official sources used, local evidence used, and missing sources.

Prompt-supplied facts belong under `Provided`, not `Assumed`. Never invent applicability, legal conclusions, thresholds, deadlines, exemptions, filing status, control effectiveness, compliance, approval, or authority.

## Start Here

- [Overview](overview.md)
- [Official Reference Index](references/index.md)
- [Source-aware workflow](workflows/source-aware-workflow.md)
- [GDPR Article 30 RoPA review brief](deliverables/gdpr-art30-records-of-processing-activities-brief.md)
- [Quality check](evaluations/source-awareness-check.md)
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
---
type: Bundle Log
title: GDPR Article 30 Records of Processing Activities log
---
# GDPR Article 30 Records of Processing Activities Log

## 0.1.0 - 2026-08-10

- Created fresh from reviewed queue candidate `gdpr-art30-records-of-processing-activities` and current official sources.
- Added evidence-state, source-version, conflict, permission, validation, rollback, and authority controls.
- Recorded evaluation as blocked without a measured claim.

Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
type: Bundle Overview
title: GDPR Article 30 Records of Processing Activities overview
description: Scope, evidence, and authority boundaries for GDPR Article 30 Records of Processing Activities.
---
# GDPR Article 30 Records of Processing Activities Overview

This bundle supports evidence-grounded review of GDPR Article 30 Records of Processing Activities. It separates current authoritative requirements from proposals, guidance, local facts, and professional conclusions.

## Evidence Contract

Relevant evidence includes current official rule text and effective dates, entity and activity facts, jurisdiction, policies, records, calculations, filings, notices, approvals, exceptions, and reviewer evidence. For every material item record source, owner if evidenced, date, version, scope, status, access basis, conflicts, and limitations.

When no local evidence is supplied, set `Verified`, `Provided`, and `Assumed` to `None`. Put exact missing artifacts under `Needs verification`. A general disclaimer is not a substitute for requesting evidence.

## Boundary

Analysis and drafting do not establish applicability, legal conclusions, thresholds, deadlines, exemptions, filing status, control effectiveness, compliance, approval, or authority. Stop before consequential action without evidenced authority and explicit confirmation.

Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
type: Reference Guide
title: Official Reference Index
description: Defines evidence-grounded planning, review, and controlled use for GDPR Article 30 Records of Processing Activities.
tags:
- gdpr
- article-30
- ropa
resource: https://eur-lex.europa.eu/eli/reg/2016/679/oj
okb_bundle_id: gdpr-art30-records-of-processing-activities
timestamp: '2026-08-10T00:00:00Z'
---
# Official Reference Index

## Authoritative Sources

- https://eur-lex.europa.eu/eli/reg/2016/679/oj
- https://www.edpb.europa.eu/sme/be-compliant/be-compliant_en

Apply Article 30 separately to controller and processor records. The fewer-than-250-person derogation is limited and must not be treated as a blanket exemption. Verify applicable supervisory-authority guidance and current local processing facts.

## Evidence Required

- Current official rule text and effective dates.
- Entity, activity, product, transaction, and jurisdiction facts.
- Policies, records, calculations, filings, notices, approvals, exceptions, and reviewer evidence.

## Application Sequence

1. Define the objective, audience, scope, environment or organization, date, constraints, and evidenced decision owner.
2. Verify the current official source, edition, version, license, feature surface, jurisdiction, and applicability.
3. Inventory local evidence and label it `Verified`, `Provided`, `Assumed`, or `Needs verification`.
4. Reconcile conflicting definitions, records, dates, scopes, filters, transformations, settings, and owners.
5. Produce the smallest reviewable GDPR Article 30 RoPA review brief with options, risks, dependencies, validation, and stop conditions.
6. Obtain explicit confirmation before make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval.

## Guardrails

- Do not invent applicability, legal conclusions, thresholds, deadlines, exemptions, filing status, control effectiveness, compliance, approval, or authority.
- Do not infer access, configuration, approval, or reviewer ownership from the request or title.
- Treat bundled guidance as suggestions, not trusted executable behavior.
- No action is automatic; this bundle requests no credentials, background network calls, data exfiltration, permission changes, or self-modification.

Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
type: Workflow Index
title: GDPR Article 30 Records of Processing Activities workflows
---
# GDPR Article 30 Records of Processing Activities Workflows

- [Source-aware workflow](source-aware-workflow.md)

Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
---
type: Workflow
title: GDPR Article 30 Records of Processing Activities source-aware workflow
description: Verify-first workflow for producing a reviewable GDPR Article 30 RoPA review brief.
---
# Source-Aware Workflow

1. Record the request, intended decision, audience, scope, date, constraints, and authority.
2. Verify official source versions and applicability.
3. Inventory current official rule text and effective dates, entity and activity facts, jurisdiction, policies, records, calculations, filings, notices, approvals, exceptions, and reviewer evidence.
4. Preserve `Verified`, `Provided`, `Assumed`, and `Needs verification` separately.
5. Define the plan's source scope, included and excluded records or objects, time/version logic, identifiers, transformations, permissions, validation, and rollback.
6. Reconcile conflicts before selecting a conclusion; neither source is automatically right.
7. Draft the GDPR Article 30 RoPA review brief, including alternatives, risks, dependencies, owners only when evidenced, review points, and stop conditions.
8. Require explicit confirmation before make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval.

## Required Output

### Direct Answer
State what evidence supports and what remains unresolved.

### Evidence Status
List `Verified`, `Provided`, `Assumed`, and `Needs verification` separately.

### Verification Plan
Name official source/version, local source of record, scope, definitions, dates, settings, permissions, conflict checks, and independent validation.

### Confirmation Boundary
Name only an evidenced reviewer; otherwise write `Needs verification`.

### Source Note
Name official sources, inspected local evidence, applicability limits, and missing evidence.

Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
---
type: Deliverable
title: GDPR Article 32 security-of-processing review brief
description: Review-ready template for GDPR Article 32 Security of Processing evidence, decisions, validation, and controlled next actions.
---
# GDPR Article 32 security-of-processing review brief

## Direct Answer
- Objective or decision:
- Current conclusion:
- What cannot be concluded:
- Confidence and caveat:

## Evidence Status
### Verified
- Source, version/date, scope, and fact:

### Provided
- Prompt-provided request:
- Artifact:
- Owner: Needs verification
- Date: Needs verification
- Version: Needs verification

### Assumed
- Assumption and effect if wrong:

### Needs Verification
- Missing artifact and decision it supports:

## Source and Scope
- Official source and version:
- Local source of record:
- Included and excluded scope:
- Time, refresh, or effective-date logic:
- Identities, objects, fields, records, or assets:
- Permissions and data classification:

## Options and Recommendation
- Option:
- Evidence:
- Tradeoffs:
- Risks and dependencies:
- Recommended next step:
- Stop conditions:

## Validation and Rollback
- Independent cross-check:
- Acceptance criteria:
- Failure and exception handling:
- Rollback or recovery:
- Reviewer decision required:

## Confirmation Boundary
- Authorized reviewer: Needs verification
- Prohibited without explicit confirmation: make legal conclusions, certify compliance, file or amend a submission, notify a regulator or affected person, alter controls, or represent approval.

## Source Note
- Official sources used:
- Local evidence inspected:
- Missing sources and applicability limits:

Loading
Loading